Thousands of Sophos firewalls still vulnerable out there to hijacking
(2023/01/19)
- Reference: 1674084615
- News link: https://www.theregister.co.uk/2023/01/18/4000_buggy_sophos_firewalls/
- Source link:
More than 4,000 public-facing Sophos firewalls remain vulnerable to a critical remote code execution bug disclosed last year and patched months later, according to security researchers.
The flaw, CVE-2022-3236, had already been exploited as a zero-day when Sophos [1]published a security advisory about the vulnerability in September 2022. At the time, the vendor [2]said the hole had been abused to target "a small set of specific organizations, primarily in the South Asia region."
The vulnerability can be exploited to gain control of a device, which can then be commandeered to probe and attack the network or outside targets.
[3]
Sophos initially issued a hotfix for some versions of the firewall, and then released an [4]formal update that squashed the bug in December 2022.
[5]
[6]
Despite that software update, however, "more than 99 percent of internet-facing Sophos Firewalls haven't upgraded to versions containing the official fix for CVE-2022-3236," according to [7]VulnCheck researchers , who wrote their own proof-of-concept exploit and scanned internet-facing Sophos firewalls to determine how likely mass exploitation actually is.
Around 93 percent of the firewalls are eligible for the hotfix, which is applied by default unless disabled by an admin. So these firewalls likely received the fix, "although mistakes do happen," VulnCheck researcher Jacob Baines wrote.
[8]
"That still leaves more than 4,000 firewalls (or about 6 percent of internet-facing Sophos Firewalls) running versions that didn't receive a hotfix and are therefore vulnerable," he said.
Sophos reportedly decimates staff
Customers seeking info on the situation from the security slinger might find they are getting a little less support than usual as UK-headquartered Sophos is [9]reportedly cutting headcount by 10 percent. That translates to 450 people axed globally.
The cuts are across the board as part of a move towards managed detection and response security services, a spokesperson said.
"Sophos is taking these steps for two main reasons: first, to ensure that we achieve the optimal balance of growth and profitability to support Sophos' long-term success, which is particularly important in the midst of a challenging and uncertain macro environment; and second, to allocate our investments across the company to support our strategic imperative to be a market leader in delivering cybersecurity as a service."
Sophos was bought by American private equity biz Thoma Bravo in a March 2020 deal that valued the concern at $3.9 billion.
As of late last week, no public proof-of-concept exploits exist for CVE-2022-3236, according to Baines. But this shouldn't provide too much comfort for anyone running unpatched versions. As the bug hunter noted: "it's only a matter of time before something is made public."
[10]Sophos fixes critical firewall hole exploited by miscreants
[11]Microsoft fixes Windows database connections it broke in November
[12]Nearly 300 MSI motherboards will run any old code in Secure Boot, no questions asked
[13]Russian criminals can't wait to hop over OpenAI's fence, use ChatGPT for evil
The security shop also published a couple of log files with indicators of exploitation attempts, which are worth checking out to help determine if your firewall has been compromised. With both, the presence of the "_discriminator" field in the login request "is sufficient to detect an exploit attempt," according to the threat hunters.
Additionally — here's the silver lining — there are limits to mass exploitation thanks to a CAPTCHA required by default to gain access. An attacker can only reach the buggy code after successfully completing the I-am-a-human test.
This is very good news for the 4,000-plus boxes running vulnerable Sophos code.
"While not impossible, programmatically solving CAPTCHAs is a high hurdle for most attackers," Baines said. "Most internet-facing Sophos Firewalls appear to have the login captcha enabled, which means, even at the most opportune times, this vulnerability was unlikely to have been successfully exploited at scale." ®
Get our [14]Tech Resources
[1] https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce
[2] https://www.theregister.com/2022/09/28/sophos_firewall_code_injection/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8jOeB1BgCggL3qgBIT-mwAAAIE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.sophos.com/en-us/security-advisories/sophos-sa-20221201-sfos-19-5-0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8jOeB1BgCggL3qgBIT-mwAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8jOeB1BgCggL3qgBIT-mwAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://vulncheck.com/blog/sophos-cve-2022-3236
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8jOeB1BgCggL3qgBIT-mwAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://techcrunch.com/2023/01/18/sophos-global-layoffs/
[10] https://www.theregister.com/2022/09/28/sophos_firewall_code_injection/
[11] https://www.theregister.com/2023/01/11/microsoft_database_connection_fix/
[12] https://www.theregister.com/2023/01/17/msi_motherboards_secure_boot/
[13] https://www.theregister.com/2023/01/18/russia_openai_chatgpt_workarounds/
[14] https://whitepapers.theregister.com/
The flaw, CVE-2022-3236, had already been exploited as a zero-day when Sophos [1]published a security advisory about the vulnerability in September 2022. At the time, the vendor [2]said the hole had been abused to target "a small set of specific organizations, primarily in the South Asia region."
The vulnerability can be exploited to gain control of a device, which can then be commandeered to probe and attack the network or outside targets.
[3]
Sophos initially issued a hotfix for some versions of the firewall, and then released an [4]formal update that squashed the bug in December 2022.
[5]
[6]
Despite that software update, however, "more than 99 percent of internet-facing Sophos Firewalls haven't upgraded to versions containing the official fix for CVE-2022-3236," according to [7]VulnCheck researchers , who wrote their own proof-of-concept exploit and scanned internet-facing Sophos firewalls to determine how likely mass exploitation actually is.
Around 93 percent of the firewalls are eligible for the hotfix, which is applied by default unless disabled by an admin. So these firewalls likely received the fix, "although mistakes do happen," VulnCheck researcher Jacob Baines wrote.
[8]
"That still leaves more than 4,000 firewalls (or about 6 percent of internet-facing Sophos Firewalls) running versions that didn't receive a hotfix and are therefore vulnerable," he said.
Sophos reportedly decimates staff
Customers seeking info on the situation from the security slinger might find they are getting a little less support than usual as UK-headquartered Sophos is [9]reportedly cutting headcount by 10 percent. That translates to 450 people axed globally.
The cuts are across the board as part of a move towards managed detection and response security services, a spokesperson said.
"Sophos is taking these steps for two main reasons: first, to ensure that we achieve the optimal balance of growth and profitability to support Sophos' long-term success, which is particularly important in the midst of a challenging and uncertain macro environment; and second, to allocate our investments across the company to support our strategic imperative to be a market leader in delivering cybersecurity as a service."
Sophos was bought by American private equity biz Thoma Bravo in a March 2020 deal that valued the concern at $3.9 billion.
As of late last week, no public proof-of-concept exploits exist for CVE-2022-3236, according to Baines. But this shouldn't provide too much comfort for anyone running unpatched versions. As the bug hunter noted: "it's only a matter of time before something is made public."
[10]Sophos fixes critical firewall hole exploited by miscreants
[11]Microsoft fixes Windows database connections it broke in November
[12]Nearly 300 MSI motherboards will run any old code in Secure Boot, no questions asked
[13]Russian criminals can't wait to hop over OpenAI's fence, use ChatGPT for evil
The security shop also published a couple of log files with indicators of exploitation attempts, which are worth checking out to help determine if your firewall has been compromised. With both, the presence of the "_discriminator" field in the login request "is sufficient to detect an exploit attempt," according to the threat hunters.
Additionally — here's the silver lining — there are limits to mass exploitation thanks to a CAPTCHA required by default to gain access. An attacker can only reach the buggy code after successfully completing the I-am-a-human test.
This is very good news for the 4,000-plus boxes running vulnerable Sophos code.
"While not impossible, programmatically solving CAPTCHAs is a high hurdle for most attackers," Baines said. "Most internet-facing Sophos Firewalls appear to have the login captcha enabled, which means, even at the most opportune times, this vulnerability was unlikely to have been successfully exploited at scale." ®
Get our [14]Tech Resources
[1] https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce
[2] https://www.theregister.com/2022/09/28/sophos_firewall_code_injection/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8jOeB1BgCggL3qgBIT-mwAAAIE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.sophos.com/en-us/security-advisories/sophos-sa-20221201-sfos-19-5-0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8jOeB1BgCggL3qgBIT-mwAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8jOeB1BgCggL3qgBIT-mwAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://vulncheck.com/blog/sophos-cve-2022-3236
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8jOeB1BgCggL3qgBIT-mwAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://techcrunch.com/2023/01/18/sophos-global-layoffs/
[10] https://www.theregister.com/2022/09/28/sophos_firewall_code_injection/
[11] https://www.theregister.com/2023/01/11/microsoft_database_connection_fix/
[12] https://www.theregister.com/2023/01/17/msi_motherboards_secure_boot/
[13] https://www.theregister.com/2023/01/18/russia_openai_chatgpt_workarounds/
[14] https://whitepapers.theregister.com/
Since this is making the rounds as if it's meaningful, I'll just repeat myself from somewhere else.
he devil's in the details.
XG 19.0.1 has a hotfix, which is applied automatically unless you deliberately disable that.
XG 19.0.0 has a hotfix, which is applied automatically unless you deliberately disable that.
The last five releases of 18.5 have a hotfix, which is applied automatically unless you deliberately disable that.
The last four releases of 18.0 have a hotfix, which is applied automatically unless you deliberately disable that.
The last six releases of 17.5 have a hotfix, which is applied automatically unless you deliberately disable that.
The last release of 17.0 has a hotfix, which is applied automatically unless you deliberately disable that.
17.5 has been EOL since November 2021, just to give an idea how available patches are.
But here's the kicker... the official, in-the-OS non-hotfix release? Was released in December and Sophos soft-releases firmware in stages. Only a small percentage of firewalls will see the 19.5 firmware as available right now. Most of the ones I manage haven't seen it. Yes, you can go out of your way to download the code form a portal and manually install it, but for most firewalls when you log on it doesn't tell you there's an update, and if you query for updates it - again - says there aren't any.
So to say 99% of eligible firewalls aren't running the fixed code is... deeply misleading. Almost all of them have hotfixed. And the non-hotfix patch requires hoops to be jumped through.
Yes, a proper admin should be aware that firmwares are available, but it's rarely good to be on the bleeding edge, and when you've got a hotfix... why rush to expose your customer to potential initial-release bugs?
This study and what it implies about Sophos or people who admin them are deeply pointless and misleading.